Identity: Add read-only identity apiserver (#90418)
This commit is contained in:
@@ -10,6 +10,7 @@ import (
|
||||
"github.com/grafana/grafana/pkg/registry/apis/datasource"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/featuretoggle"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/folders"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/identity"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/peakq"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/playlist"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/query"
|
||||
@@ -32,6 +33,7 @@ func ProvideRegistryServiceSink(
|
||||
_ *datasource.DataSourceAPIBuilder,
|
||||
_ *folders.FolderAPIBuilder,
|
||||
_ *peakq.PeakQAPIBuilder,
|
||||
_ *identity.IdentityAPIBuilder,
|
||||
_ *scope.ScopeAPIBuilder,
|
||||
_ *query.QueryAPIBuilder,
|
||||
_ *notifications.NotificationsAPIBuilder,
|
||||
|
||||
@@ -0,0 +1,130 @@
|
||||
package identity
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strconv"
|
||||
|
||||
"k8s.io/apimachinery/pkg/apis/meta/internalversion"
|
||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
"k8s.io/apimachinery/pkg/runtime"
|
||||
"k8s.io/apiserver/pkg/registry/rest"
|
||||
|
||||
common "github.com/grafana/grafana/pkg/apimachinery/apis/common/v0alpha1"
|
||||
identity "github.com/grafana/grafana/pkg/apimachinery/apis/identity/v0alpha1"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
||||
"github.com/grafana/grafana/pkg/services/apiserver/endpoints/request"
|
||||
"github.com/grafana/grafana/pkg/services/user"
|
||||
)
|
||||
|
||||
var (
|
||||
_ rest.Scoper = (*legacyServiceAccountStorage)(nil)
|
||||
_ rest.SingularNameProvider = (*legacyServiceAccountStorage)(nil)
|
||||
_ rest.Getter = (*legacyServiceAccountStorage)(nil)
|
||||
_ rest.Lister = (*legacyServiceAccountStorage)(nil)
|
||||
_ rest.Storage = (*legacyServiceAccountStorage)(nil)
|
||||
)
|
||||
|
||||
type legacyServiceAccountStorage struct {
|
||||
service user.Service
|
||||
tableConverter rest.TableConvertor
|
||||
resourceInfo common.ResourceInfo
|
||||
}
|
||||
|
||||
func (s *legacyServiceAccountStorage) New() runtime.Object {
|
||||
return s.resourceInfo.NewFunc()
|
||||
}
|
||||
|
||||
func (s *legacyServiceAccountStorage) Destroy() {}
|
||||
|
||||
func (s *legacyServiceAccountStorage) NamespaceScoped() bool {
|
||||
return true // namespace == org
|
||||
}
|
||||
|
||||
func (s *legacyServiceAccountStorage) GetSingularName() string {
|
||||
return s.resourceInfo.GetSingularName()
|
||||
}
|
||||
|
||||
func (s *legacyServiceAccountStorage) NewList() runtime.Object {
|
||||
return s.resourceInfo.NewListFunc()
|
||||
}
|
||||
|
||||
func (s *legacyServiceAccountStorage) ConvertToTable(ctx context.Context, object runtime.Object, tableOptions runtime.Object) (*metav1.Table, error) {
|
||||
return s.tableConverter.ConvertToTable(ctx, object, tableOptions)
|
||||
}
|
||||
|
||||
func (s *legacyServiceAccountStorage) List(ctx context.Context, options *internalversion.ListOptions) (runtime.Object, error) {
|
||||
ns, err := request.NamespaceInfoFrom(ctx, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
query := &user.ListUsersCommand{
|
||||
OrgID: ns.OrgID,
|
||||
Limit: options.Limit,
|
||||
IsServiceAccount: true,
|
||||
}
|
||||
if options.Continue != "" {
|
||||
query.ContinueID, err = strconv.ParseInt(options.Continue, 10, 64)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("invalid continue token")
|
||||
}
|
||||
}
|
||||
|
||||
found, err := s.service.List(ctx, query)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
list := &identity.ServiceAccountList{}
|
||||
for _, item := range found.Users {
|
||||
list.Items = append(list.Items, *toSAItem(item, ns.Value))
|
||||
}
|
||||
if found.ContinueID > 0 {
|
||||
list.ListMeta.Continue = strconv.FormatInt(found.ContinueID, 10)
|
||||
}
|
||||
if found.RV > 0 {
|
||||
list.ListMeta.ResourceVersion = strconv.FormatInt(found.RV, 10)
|
||||
}
|
||||
return list, err
|
||||
}
|
||||
|
||||
func toSAItem(u *user.User, ns string) *identity.ServiceAccount {
|
||||
item := &identity.ServiceAccount{
|
||||
ObjectMeta: metav1.ObjectMeta{
|
||||
Name: u.UID,
|
||||
Namespace: ns,
|
||||
ResourceVersion: fmt.Sprintf("%d", u.Updated.UnixMilli()),
|
||||
CreationTimestamp: metav1.NewTime(u.Created),
|
||||
},
|
||||
Spec: identity.ServiceAccountSpec{
|
||||
Name: u.Name,
|
||||
Email: u.Email,
|
||||
EmailVerified: u.EmailVerified,
|
||||
Disabled: u.IsDisabled,
|
||||
},
|
||||
}
|
||||
obj, _ := utils.MetaAccessor(item)
|
||||
obj.SetUpdatedTimestamp(&u.Updated)
|
||||
obj.SetOriginInfo(&utils.ResourceOriginInfo{
|
||||
Name: "SQL",
|
||||
Path: strconv.FormatInt(u.ID, 10),
|
||||
})
|
||||
return item
|
||||
}
|
||||
|
||||
func (s *legacyServiceAccountStorage) Get(ctx context.Context, name string, options *metav1.GetOptions) (runtime.Object, error) {
|
||||
ns, err := request.NamespaceInfoFrom(ctx, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
found, err := s.service.GetByUID(ctx, &user.GetUserByUIDQuery{
|
||||
OrgID: ns.OrgID,
|
||||
UID: name,
|
||||
})
|
||||
if found == nil || err != nil {
|
||||
return nil, s.resourceInfo.NewNotFound(name)
|
||||
}
|
||||
if !found.IsServiceAccount {
|
||||
return nil, s.resourceInfo.NewNotFound(name) // looking up the wrong type
|
||||
}
|
||||
return toUserItem(found, ns.Value), nil
|
||||
}
|
||||
@@ -0,0 +1,119 @@
|
||||
package identity
|
||||
|
||||
import (
|
||||
"context"
|
||||
"strconv"
|
||||
|
||||
"k8s.io/apimachinery/pkg/apis/meta/internalversion"
|
||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
"k8s.io/apimachinery/pkg/runtime"
|
||||
"k8s.io/apiserver/pkg/registry/rest"
|
||||
|
||||
common "github.com/grafana/grafana/pkg/apimachinery/apis/common/v0alpha1"
|
||||
identity "github.com/grafana/grafana/pkg/apimachinery/apis/identity/v0alpha1"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
||||
"github.com/grafana/grafana/pkg/services/apiserver/endpoints/request"
|
||||
"github.com/grafana/grafana/pkg/services/team"
|
||||
)
|
||||
|
||||
var (
|
||||
_ rest.Scoper = (*legacyTeamStorage)(nil)
|
||||
_ rest.SingularNameProvider = (*legacyTeamStorage)(nil)
|
||||
_ rest.Getter = (*legacyTeamStorage)(nil)
|
||||
_ rest.Lister = (*legacyTeamStorage)(nil)
|
||||
_ rest.Storage = (*legacyTeamStorage)(nil)
|
||||
)
|
||||
|
||||
type legacyTeamStorage struct {
|
||||
service team.Service
|
||||
tableConverter rest.TableConvertor
|
||||
resourceInfo common.ResourceInfo
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) New() runtime.Object {
|
||||
return s.resourceInfo.NewFunc()
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) Destroy() {}
|
||||
|
||||
func (s *legacyTeamStorage) NamespaceScoped() bool {
|
||||
return true // namespace == org
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) GetSingularName() string {
|
||||
return s.resourceInfo.GetSingularName()
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) NewList() runtime.Object {
|
||||
return s.resourceInfo.NewListFunc()
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) ConvertToTable(ctx context.Context, object runtime.Object, tableOptions runtime.Object) (*metav1.Table, error) {
|
||||
return s.tableConverter.ConvertToTable(ctx, object, tableOptions)
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) doList(ctx context.Context, ns string, query *team.ListTeamsCommand) (*identity.TeamList, error) {
|
||||
if query.Limit < 1 {
|
||||
query.Limit = 100
|
||||
}
|
||||
teams, err := s.service.ListTeams(ctx, query)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
list := &identity.TeamList{}
|
||||
for _, team := range teams {
|
||||
item := identity.Team{
|
||||
ObjectMeta: metav1.ObjectMeta{
|
||||
Name: team.UID,
|
||||
Namespace: ns,
|
||||
CreationTimestamp: metav1.NewTime(team.Created),
|
||||
ResourceVersion: strconv.FormatInt(team.Updated.UnixMilli(), 10),
|
||||
},
|
||||
Spec: identity.TeamSpec{
|
||||
Title: team.Name,
|
||||
Email: team.Email,
|
||||
},
|
||||
}
|
||||
meta, err := utils.MetaAccessor(&item)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
meta.SetUpdatedTimestamp(&team.Updated)
|
||||
meta.SetOriginInfo(&utils.ResourceOriginInfo{
|
||||
Name: "SQL",
|
||||
Path: strconv.FormatInt(team.ID, 10),
|
||||
})
|
||||
list.Items = append(list.Items, item)
|
||||
}
|
||||
return list, nil
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) List(ctx context.Context, options *internalversion.ListOptions) (runtime.Object, error) {
|
||||
ns, err := request.NamespaceInfoFrom(ctx, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return s.doList(ctx, ns.Value, &team.ListTeamsCommand{
|
||||
Limit: int(options.Limit),
|
||||
OrgID: ns.OrgID,
|
||||
})
|
||||
}
|
||||
|
||||
func (s *legacyTeamStorage) Get(ctx context.Context, name string, options *metav1.GetOptions) (runtime.Object, error) {
|
||||
ns, err := request.NamespaceInfoFrom(ctx, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
rsp, err := s.doList(ctx, ns.Value, &team.ListTeamsCommand{
|
||||
Limit: 1,
|
||||
OrgID: ns.OrgID,
|
||||
UID: name,
|
||||
})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if len(rsp.Items) > 0 {
|
||||
return &rsp.Items[0], nil
|
||||
}
|
||||
return nil, s.resourceInfo.NewNotFound(name)
|
||||
}
|
||||
@@ -0,0 +1,130 @@
|
||||
package identity
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strconv"
|
||||
|
||||
"k8s.io/apimachinery/pkg/apis/meta/internalversion"
|
||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
"k8s.io/apimachinery/pkg/runtime"
|
||||
"k8s.io/apiserver/pkg/registry/rest"
|
||||
|
||||
common "github.com/grafana/grafana/pkg/apimachinery/apis/common/v0alpha1"
|
||||
identity "github.com/grafana/grafana/pkg/apimachinery/apis/identity/v0alpha1"
|
||||
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
||||
"github.com/grafana/grafana/pkg/services/apiserver/endpoints/request"
|
||||
"github.com/grafana/grafana/pkg/services/user"
|
||||
)
|
||||
|
||||
var (
|
||||
_ rest.Scoper = (*legacyUserStorage)(nil)
|
||||
_ rest.SingularNameProvider = (*legacyUserStorage)(nil)
|
||||
_ rest.Getter = (*legacyUserStorage)(nil)
|
||||
_ rest.Lister = (*legacyUserStorage)(nil)
|
||||
_ rest.Storage = (*legacyUserStorage)(nil)
|
||||
)
|
||||
|
||||
type legacyUserStorage struct {
|
||||
service user.Service
|
||||
tableConverter rest.TableConvertor
|
||||
resourceInfo common.ResourceInfo
|
||||
}
|
||||
|
||||
func (s *legacyUserStorage) New() runtime.Object {
|
||||
return s.resourceInfo.NewFunc()
|
||||
}
|
||||
|
||||
func (s *legacyUserStorage) Destroy() {}
|
||||
|
||||
func (s *legacyUserStorage) NamespaceScoped() bool {
|
||||
return true // namespace == org
|
||||
}
|
||||
|
||||
func (s *legacyUserStorage) GetSingularName() string {
|
||||
return s.resourceInfo.GetSingularName()
|
||||
}
|
||||
|
||||
func (s *legacyUserStorage) NewList() runtime.Object {
|
||||
return s.resourceInfo.NewListFunc()
|
||||
}
|
||||
|
||||
func (s *legacyUserStorage) ConvertToTable(ctx context.Context, object runtime.Object, tableOptions runtime.Object) (*metav1.Table, error) {
|
||||
return s.tableConverter.ConvertToTable(ctx, object, tableOptions)
|
||||
}
|
||||
|
||||
func (s *legacyUserStorage) List(ctx context.Context, options *internalversion.ListOptions) (runtime.Object, error) {
|
||||
ns, err := request.NamespaceInfoFrom(ctx, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
query := &user.ListUsersCommand{
|
||||
OrgID: ns.OrgID,
|
||||
Limit: options.Limit,
|
||||
}
|
||||
if options.Continue != "" {
|
||||
query.ContinueID, err = strconv.ParseInt(options.Continue, 10, 64)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("invalid continue token")
|
||||
}
|
||||
}
|
||||
|
||||
found, err := s.service.List(ctx, query)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
list := &identity.UserList{}
|
||||
for _, item := range found.Users {
|
||||
list.Items = append(list.Items, *toUserItem(item, ns.Value))
|
||||
}
|
||||
if found.ContinueID > 0 {
|
||||
list.ListMeta.Continue = strconv.FormatInt(found.ContinueID, 10)
|
||||
}
|
||||
if found.RV > 0 {
|
||||
list.ListMeta.ResourceVersion = strconv.FormatInt(found.RV, 10)
|
||||
}
|
||||
return list, err
|
||||
}
|
||||
|
||||
func toUserItem(u *user.User, ns string) *identity.User {
|
||||
item := &identity.User{
|
||||
ObjectMeta: metav1.ObjectMeta{
|
||||
Name: u.UID,
|
||||
Namespace: ns,
|
||||
ResourceVersion: fmt.Sprintf("%d", u.Updated.UnixMilli()),
|
||||
CreationTimestamp: metav1.NewTime(u.Created),
|
||||
},
|
||||
Spec: identity.UserSpec{
|
||||
Name: u.Name,
|
||||
Login: u.Login,
|
||||
Email: u.Email,
|
||||
EmailVerified: u.EmailVerified,
|
||||
Disabled: u.IsDisabled,
|
||||
},
|
||||
}
|
||||
obj, _ := utils.MetaAccessor(item)
|
||||
obj.SetUpdatedTimestamp(&u.Updated)
|
||||
obj.SetOriginInfo(&utils.ResourceOriginInfo{
|
||||
Name: "SQL",
|
||||
Path: strconv.FormatInt(u.ID, 10),
|
||||
})
|
||||
return item
|
||||
}
|
||||
|
||||
func (s *legacyUserStorage) Get(ctx context.Context, name string, options *metav1.GetOptions) (runtime.Object, error) {
|
||||
ns, err := request.NamespaceInfoFrom(ctx, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
found, err := s.service.GetByUID(ctx, &user.GetUserByUIDQuery{
|
||||
OrgID: ns.OrgID,
|
||||
UID: name,
|
||||
})
|
||||
if found == nil || err != nil {
|
||||
return nil, s.resourceInfo.NewNotFound(name)
|
||||
}
|
||||
if found.IsServiceAccount {
|
||||
return nil, s.resourceInfo.NewNotFound(name) // looking up the wrong type
|
||||
}
|
||||
return toUserItem(found, ns.Value), nil
|
||||
}
|
||||
@@ -0,0 +1,196 @@
|
||||
package identity
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
"k8s.io/apimachinery/pkg/runtime"
|
||||
"k8s.io/apimachinery/pkg/runtime/schema"
|
||||
"k8s.io/apimachinery/pkg/runtime/serializer"
|
||||
"k8s.io/apiserver/pkg/authorization/authorizer"
|
||||
"k8s.io/apiserver/pkg/registry/generic"
|
||||
"k8s.io/apiserver/pkg/registry/rest"
|
||||
genericapiserver "k8s.io/apiserver/pkg/server"
|
||||
common "k8s.io/kube-openapi/pkg/common"
|
||||
|
||||
identity "github.com/grafana/grafana/pkg/apimachinery/apis/identity/v0alpha1"
|
||||
identityapi "github.com/grafana/grafana/pkg/apimachinery/identity"
|
||||
grafanarest "github.com/grafana/grafana/pkg/apiserver/rest"
|
||||
"github.com/grafana/grafana/pkg/services/apiserver/builder"
|
||||
gapiutil "github.com/grafana/grafana/pkg/services/apiserver/utils"
|
||||
"github.com/grafana/grafana/pkg/services/featuremgmt"
|
||||
"github.com/grafana/grafana/pkg/services/team"
|
||||
"github.com/grafana/grafana/pkg/services/user"
|
||||
)
|
||||
|
||||
var _ builder.APIGroupBuilder = (*IdentityAPIBuilder)(nil)
|
||||
|
||||
// This is used just so wire has something unique to return
|
||||
type IdentityAPIBuilder struct {
|
||||
svcTeam team.Service
|
||||
svcUser user.Service
|
||||
}
|
||||
|
||||
func RegisterAPIService(
|
||||
features featuremgmt.FeatureToggles,
|
||||
apiregistration builder.APIRegistrar,
|
||||
svcTeam team.Service,
|
||||
svcUser user.Service,
|
||||
|
||||
) *IdentityAPIBuilder {
|
||||
if !features.IsEnabledGlobally(featuremgmt.FlagGrafanaAPIServerWithExperimentalAPIs) {
|
||||
return nil // skip registration unless opting into experimental apis
|
||||
}
|
||||
|
||||
builder := &IdentityAPIBuilder{
|
||||
svcTeam: svcTeam,
|
||||
svcUser: svcUser,
|
||||
}
|
||||
apiregistration.RegisterAPI(builder)
|
||||
return builder
|
||||
}
|
||||
|
||||
func (b *IdentityAPIBuilder) GetGroupVersion() schema.GroupVersion {
|
||||
return identity.SchemeGroupVersion
|
||||
}
|
||||
|
||||
func (b *IdentityAPIBuilder) InstallSchema(scheme *runtime.Scheme) error {
|
||||
if err := identity.AddKnownTypes(scheme, identity.VERSION); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Link this version to the internal representation.
|
||||
// This is used for server-side-apply (PATCH), and avoids the error:
|
||||
// "no kind is registered for the type"
|
||||
if err := identity.AddKnownTypes(scheme, runtime.APIVersionInternal); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// If multiple versions exist, then register conversions from zz_generated.conversion.go
|
||||
// if err := playlist.RegisterConversions(scheme); err != nil {
|
||||
// return err
|
||||
// }
|
||||
metav1.AddToGroupVersion(scheme, identity.SchemeGroupVersion)
|
||||
return scheme.SetVersionPriority(identity.SchemeGroupVersion)
|
||||
}
|
||||
|
||||
func (b *IdentityAPIBuilder) GetAPIGroupInfo(
|
||||
scheme *runtime.Scheme,
|
||||
codecs serializer.CodecFactory, // pointer?
|
||||
optsGetter generic.RESTOptionsGetter,
|
||||
dualWriteBuilder grafanarest.DualWriteBuilder,
|
||||
) (*genericapiserver.APIGroupInfo, error) {
|
||||
apiGroupInfo := genericapiserver.NewDefaultAPIGroupInfo(identity.GROUP, scheme, metav1.ParameterCodec, codecs)
|
||||
storage := map[string]rest.Storage{}
|
||||
|
||||
team := identity.TeamResourceInfo
|
||||
teamStore := &legacyTeamStorage{
|
||||
service: b.svcTeam,
|
||||
resourceInfo: team,
|
||||
tableConverter: gapiutil.NewTableConverter(
|
||||
team.GroupResource(),
|
||||
[]metav1.TableColumnDefinition{
|
||||
{Name: "Name", Type: "string", Format: "name"},
|
||||
{Name: "Title", Type: "string", Format: "string", Description: "The team name"},
|
||||
{Name: "Email", Type: "string", Format: "string", Description: "team email"},
|
||||
{Name: "Created At", Type: "date"},
|
||||
},
|
||||
func(obj any) ([]interface{}, error) {
|
||||
m, ok := obj.(*identity.Team)
|
||||
if !ok {
|
||||
return nil, fmt.Errorf("expected playlist")
|
||||
}
|
||||
return []interface{}{
|
||||
m.Name,
|
||||
m.Spec.Title,
|
||||
m.Spec.Email,
|
||||
m.CreationTimestamp.UTC().Format(time.RFC3339),
|
||||
}, nil
|
||||
},
|
||||
),
|
||||
}
|
||||
storage[team.StoragePath()] = teamStore
|
||||
|
||||
user := identity.UserResourceInfo
|
||||
userStore := &legacyUserStorage{
|
||||
service: b.svcUser,
|
||||
resourceInfo: user,
|
||||
tableConverter: gapiutil.NewTableConverter(
|
||||
user.GroupResource(),
|
||||
[]metav1.TableColumnDefinition{
|
||||
{Name: "Name", Type: "string", Format: "name"},
|
||||
{Name: "Login", Type: "string", Format: "string", Description: "The user login"},
|
||||
{Name: "Email", Type: "string", Format: "string", Description: "The user email"},
|
||||
{Name: "Created At", Type: "date"},
|
||||
},
|
||||
func(obj any) ([]interface{}, error) {
|
||||
u, ok := obj.(*identity.User)
|
||||
if ok {
|
||||
return []interface{}{
|
||||
u.Name,
|
||||
u.Spec.Login,
|
||||
u.Spec.Email,
|
||||
u.CreationTimestamp.UTC().Format(time.RFC3339),
|
||||
}, nil
|
||||
}
|
||||
return nil, fmt.Errorf("expected user")
|
||||
},
|
||||
),
|
||||
}
|
||||
storage[user.StoragePath()] = userStore
|
||||
|
||||
sa := identity.ServiceAccountResourceInfo
|
||||
saStore := &legacyServiceAccountStorage{
|
||||
service: b.svcUser,
|
||||
resourceInfo: sa,
|
||||
tableConverter: gapiutil.NewTableConverter(
|
||||
user.GroupResource(),
|
||||
[]metav1.TableColumnDefinition{
|
||||
{Name: "Name", Type: "string", Format: "name"},
|
||||
{Name: "Account", Type: "string", Format: "string", Description: "The service account email"},
|
||||
{Name: "Email", Type: "string", Format: "string", Description: "The user email"},
|
||||
{Name: "Created At", Type: "date"},
|
||||
},
|
||||
func(obj any) ([]interface{}, error) {
|
||||
u, ok := obj.(*identity.ServiceAccount)
|
||||
if ok {
|
||||
return []interface{}{
|
||||
u.Name,
|
||||
u.Spec.Name,
|
||||
u.Spec.Email,
|
||||
u.CreationTimestamp.UTC().Format(time.RFC3339),
|
||||
}, nil
|
||||
}
|
||||
return nil, fmt.Errorf("expected user")
|
||||
},
|
||||
),
|
||||
}
|
||||
storage[sa.StoragePath()] = saStore
|
||||
|
||||
apiGroupInfo.VersionedResourcesStorageMap[identity.VERSION] = storage
|
||||
return &apiGroupInfo, nil
|
||||
}
|
||||
|
||||
func (b *IdentityAPIBuilder) GetOpenAPIDefinitions() common.GetOpenAPIDefinitions {
|
||||
return identity.GetOpenAPIDefinitions
|
||||
}
|
||||
|
||||
func (b *IdentityAPIBuilder) GetAPIRoutes() *builder.APIRoutes {
|
||||
return nil // no custom API routes
|
||||
}
|
||||
|
||||
func (b *IdentityAPIBuilder) GetAuthorizer() authorizer.Authorizer {
|
||||
return authorizer.AuthorizerFunc(
|
||||
func(ctx context.Context, a authorizer.Attributes) (authorizer.Decision, string, error) {
|
||||
user, err := identityapi.GetRequester(ctx)
|
||||
if err != nil {
|
||||
return authorizer.DecisionDeny, "no identity found", err
|
||||
}
|
||||
if user.GetIsGrafanaAdmin() {
|
||||
return authorizer.DecisionAllow, "", nil
|
||||
}
|
||||
return authorizer.DecisionDeny, "only grafana admins have access for now", nil
|
||||
})
|
||||
}
|
||||
@@ -9,6 +9,7 @@ import (
|
||||
"github.com/grafana/grafana/pkg/registry/apis/datasource"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/featuretoggle"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/folders"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/identity"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/peakq"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/playlist"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/query"
|
||||
@@ -32,6 +33,7 @@ var WireSet = wire.NewSet(
|
||||
featuretoggle.RegisterAPIService,
|
||||
datasource.RegisterAPIService,
|
||||
folders.RegisterAPIService,
|
||||
identity.RegisterAPIService,
|
||||
peakq.RegisterAPIService,
|
||||
service.RegisterAPIService,
|
||||
query.RegisterAPIService,
|
||||
|
||||
@@ -93,15 +93,6 @@ func GetCoreKinds() ([]CoreKind, error) {
|
||||
CueFile: rolebindingCue,
|
||||
})
|
||||
|
||||
teamCue, err := loadCueFile(ctx, filepath.Join(root, "./kinds/team/team_kind.cue"))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
kinds = append(kinds, CoreKind{
|
||||
Name: "team",
|
||||
CueFile: teamCue,
|
||||
})
|
||||
|
||||
return kinds, nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user